Geschreven door studenten die geslaagd zijn Direct beschikbaar na je betaling Online lezen of als PDF Verkeerd document? Gratis ruilen 4,6 TrustPilot
logo-home
Tentamen (uitwerkingen)

WGU D430: Fundamentals of Information Security – Risk Management, Compliance & Cryptography Study Course Review Questions and answers updated 2026

Beoordeling
-
Verkocht
-
Pagina's
46
Cijfer
A+
Geüpload op
09-03-2026
Geschreven in
2025/2026

WGU D430: Fundamentals of Information Security – Risk Management, Compliance & Cryptography Study Course Review Questions and answers updated 2026 Vulnerabilities - correct answer weaknesses or holes of an asset that threats can exploit to cause harm. Ex; could be an operating system, the physical location of a building, servers generating more heat that the air-conditioning can handle, etc.. Risk - correct answer the likelihood that something bad will happen because of the potential for a threat to exploit a vulnerability. M; pinpoint the high likelihood of THESE and spend your time mitigating these more likely attacks instead of spreading your time evenly with less likely attacks. Impact - correct answer THIS takes into account the value of the asset being threatened and uses it to calculate risk. Ex; if the asset is your journal, you can say there is no risk. If the asset is your bank account information, you can say the risk is very high. M; the US national security agency (NSA) added THIS factor to the threat/vulnerability/risk equation. Risk management process - correct answer identify assets identify threats assess vulnerabilities assess risks mitigate risks. Identify important assets, figure potential threats against them, assess vulnerabilities, then take steps to mitigate these risks. Identify assets (risk management process) - correct answer THIS is one of the first and most important parts of risk management. If you can't identify the impact, then protection becomes a difficult task. Ex; acquisition of another company leads to THIS possibly being required to keep the business functional. Identify threats (risk management process) - correct answer once the impact of assets are assessed, THIS is required to see how potential attacks might affect the assets. M; being concerned with losing control of data, maintaining accurate data, and keeping the system up and running allows you to be able to look at areas of vulnerability and potential risk. Assess vulnerabilities (risk management process) - correct answer assets can have millions of threats, but only a fraction will be relevant; THIS is done to see if those relevant threats pose a risk. Ex; if data is exposed, it could lead to a breach. If your data is encrypted, this is not a risk. Ex; if the system goes down, business operations will also go down, this is a risk.

Meer zien Lees minder
Instelling
WGU D430 / WGU C836 Information Security
Vak
WGU D430 / WGU C836 Information Security

Voorbeeld van de inhoud

WGU D430: Fundamentals of Information Security – Risk
Management, Compliance & Cryptography Study Course
Review Questions and answers updated 2026

Vulnerabilities - correct answer weaknesses or holes of an asset that threats can
exploit to cause harm.


Ex; could be an operating system, the physical location of a building, servers generating
more heat that the air-conditioning can handle, etc..


Risk - correct answer the likelihood that something bad will happen because of the
potential for a threat to exploit a vulnerability.


M; pinpoint the high likelihood of THESE and spend your time mitigating these more
likely attacks instead of spreading your time evenly with less likely attacks.


Impact - correct answer THIS takes into account the value of the asset being
threatened and uses it to calculate risk.


Ex; if the asset is your journal, you can say there is no risk. If the asset is your bank
account information, you can say the risk is very high.


M; the US national security agency (NSA) added THIS factor to the
threat/vulnerability/risk equation.


Risk management process - correct answer identify assets > identify threats > assess
vulnerabilities > assess risks > mitigate risks.


Identify important assets, figure potential threats against them, assess vulnerabilities,
then take steps to mitigate these risks.

,Identify assets (risk management process) - correct answer THIS is one of the first and
most important parts of risk management. If you can't identify the impact, then
protection becomes a difficult task.


Ex; acquisition of another company leads to THIS possibly being required to keep the
business functional.


Identify threats (risk management process) - correct answer once the impact of assets
are assessed, THIS is required to see how potential attacks might affect the assets.


M; being concerned with losing control of data, maintaining accurate data, and keeping
the system up and running allows you to be able to look at areas of vulnerability and
potential risk.


Assess vulnerabilities (risk management process) - correct answer assets can have
millions of threats, but only a fraction will be relevant; THIS is done to see if those
relevant threats pose a risk.


Ex; if data is exposed, it could lead to a breach. If your data is encrypted, this is not a
risk.


Ex; if the system goes down, business operations will also go down, this is a risk.


Assess risks (risk management process) - correct answer once the threats and
vulnerabilities are identified, THIS is done to have an overall idea of the risk so you can
start to mitigate them.


M; a vulnerability with no matching threat or a threat with no matching vulnerability does
not constitute a risk.


Mitigate risks (risk management process) - correct answer THIS is putting measures
(called controls) in place to account for each threat. There are three categories of
control: physical, logical, and administrative.

,Physical controls/measures (mitigate risks) - correct answer THIS protects the physical
environment in which your systems sit or where your data is stored. Also controls
access of such environments.


Ex; includes fences, gates, locks, bollards, guards, and cameras, but also systems that
maintain the physical environment, such as heating and air-conditioning systems, fire
suppression systems, and backup power generators.


M; one of the most critical controls. Makes other controls useless if an attacker has
direct access to your system.


Logical (or technical) controls/measures (mitigate risks) - correct answer THIS protects
the systems, networks, and environments that process, transmit, and store your data.


Ex; THIS can be things such as passwords, encryption, access controls, firewalls, and
intrusion detection systems.


M; enables the prevention of unauthorized activities unless the attacker is able to
subvert the controls.


Administrative controls/measures (mitigate risks) - correct answer THIS dictates how
the users of your environment should behave; the rules, laws, policies, procedures,
guidelines, and other items that are "paper" in nature.


M; an important aspect of THIS is the ability to enforce it. Can cause threats and
vulnerabilities if left unchecked.


Incident response - correct answer something to be done in the event of an attack and
should be directed in a way that is based on the impact the attack has towards the
organization.

, M; steps in THIS process: preparation, detection and analysis, containment, eradication,
recovery, post-incident activity.


Preparation (incident response) - correct answer the phase where things are done
before an incident occurs.


Ex; policies and procedures that govern incident response and handling, conducting
training for the response team and those who report incidents, and developing and
maintaining documentation.


M; decisions should already be made regarding what needs to be done, who needs to
do it, and how to do it.


Detection and analysis (incident response) - correct answer the phase where issues
are detected, a decision is made whether it's actually an incident, and the appropriate
response to it. The second part of this requires human judgement and decision making.


M; usually detected with a security tool or service such as an intrusion detection system
(IDS), antivirus (AV) software, firewall logs, proxy logs, or alerts from a security
information and event monitoring (SIEM) tool or managed security service provider
(MSSP).


Containment (incident response) - correct answer THIS involves stopping an incident
from doing anymore damage or at least to lessen any ongoing harm.


Ex; if malware-infected by a remote attacker, this might involve disconnection, blocking
with a firewall, and updating signatures or rules on an intrusion prevention system (IPS)
to halt the malware traffic.


Eradication (incident response) - correct answer THIS involves attempting to remove
the effects of the issue from your environment.

Geschreven voor

Instelling
WGU D430 / WGU C836 Information Security
Vak
WGU D430 / WGU C836 Information Security

Documentinformatie

Geüpload op
9 maart 2026
Aantal pagina's
46
Geschreven in
2025/2026
Type
Tentamen (uitwerkingen)
Bevat
Vragen en antwoorden

Onderwerpen

$12.49
Krijg toegang tot het volledige document:

Verkeerd document? Gratis ruilen Binnen 14 dagen na aankoop en voor het downloaden kun je een ander document kiezen. Je kunt het bedrag gewoon opnieuw besteden.
Geschreven door studenten die geslaagd zijn
Direct beschikbaar na je betaling
Online lezen of als PDF

Maak kennis met de verkoper

Seller avatar
De reputatie van een verkoper is gebaseerd op het aantal documenten dat iemand tegen betaling verkocht heeft en de beoordelingen die voor die items ontvangen zijn. Er zijn drie niveau’s te onderscheiden: brons, zilver en goud. Hoe beter de reputatie, hoe meer de kwaliteit van zijn of haar werk te vertrouwen is.
KieranKent55 NONE
Volgen Je moet ingelogd zijn om studenten of vakken te kunnen volgen
Verkocht
43
Lid sinds
2 jaar
Aantal volgers
18
Documenten
6452
Laatst verkocht
3 maanden geleden

3.6

9 beoordelingen

5
4
4
1
3
2
2
0
1
2

Recent door jou bekeken

Waarom studenten kiezen voor Stuvia

Gemaakt door medestudenten, geverifieerd door reviews

Kwaliteit die je kunt vertrouwen: geschreven door studenten die slaagden en beoordeeld door anderen die dit document gebruikten.

Niet tevreden? Kies een ander document

Geen zorgen! Je kunt voor hetzelfde geld direct een ander document kiezen dat beter past bij wat je zoekt.

Betaal zoals je wilt, start meteen met leren

Geen abonnement, geen verplichtingen. Betaal zoals je gewend bent via iDeal of creditcard en download je PDF-document meteen.

Student with book image

“Gekocht, gedownload en geslaagd. Zo makkelijk kan het dus zijn.”

Alisha Student

Bezig met je bronvermelding?

Maak nauwkeurige citaten in APA, MLA en Harvard met onze gratis bronnengenerator.

Bezig met je bronvermelding?

Veelgestelde vragen